CVE-2024-40488

A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lopalopa:live_membership_system:1.0:*:*:*:*:*:*:*

History

28 Apr 2025, 14:24

Type Values Removed Values Added
First Time Lopalopa
Lopalopa live Membership System
CPE cpe:2.3:a:lopalopa:live_membership_system:1.0:*:*:*:*:*:*:*
References () https://capec.mitre.org/data/definitions/62.html - () https://capec.mitre.org/data/definitions/62.html - Third Party Advisory
References () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Live%20Membership%20System%20v1.0/CSRF.pdf - () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Live%20Membership%20System%20v1.0/CSRF.pdf - Exploit, Third Party Advisory

Information

Published : 2024-08-12 13:38

Updated : 2025-04-28 14:24


NVD link : CVE-2024-40488

Mitre link : CVE-2024-40488

CVE.ORG link : CVE-2024-40488


JSON object : View

Products Affected

lopalopa

  • live_membership_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)